[Apollo] Advisories Red Hat Advisories Statistics light light Login

RHSA-2024:2888

Security
Issued at: 2024-05-16
launch
Open original
Override

Synopsis

Important: thunderbird security update



Description

Mozilla Thunderbird is a standalone mail and newsgroup client.

This update upgrades Thunderbird to version 115.11.0.

Security Fix(es):

* firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)

* firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767)

* firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768)

* firefox: Cross-origin responses could be distinguished between script and

non-script content-types (CVE-2024-4769)

* firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770)

* firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and

Thunderbird 115.11 (CVE-2024-4777)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Red Hat Enterprise Linux for ARM 64 - 9 Red Hat Enterprise Linux for IBM z Systems - 9 Red Hat Enterprise Linux for Power, little endian - 9 Red Hat Enterprise Linux for x86_64 - 9

Fixes

2280382 2280383 2280384 2280385 2280386 2280387

CVEs

CVE-2024-4367 CVE-2024-4767 CVE-2024-4768 CVE-2024-4769 CVE-2024-4770 CVE-2024-4777

Affected packages

thunderbird-0:115.11.0-1.el9_4.aarch64 thunderbird-0:115.11.0-1.el9_4.ppc64le thunderbird-0:115.11.0-1.el9_4.s390x thunderbird-0:115.11.0-1.el9_4.src thunderbird-0:115.11.0-1.el9_4.x86_64 thunderbird-debuginfo-0:115.11.0-1.el9_4.aarch64 thunderbird-debuginfo-0:115.11.0-1.el9_4.ppc64le thunderbird-debuginfo-0:115.11.0-1.el9_4.s390x thunderbird-debuginfo-0:115.11.0-1.el9_4.x86_64 thunderbird-debugsource-0:115.11.0-1.el9_4.aarch64 thunderbird-debugsource-0:115.11.0-1.el9_4.ppc64le thunderbird-debugsource-0:115.11.0-1.el9_4.s390x thunderbird-debugsource-0:115.11.0-1.el9_4.x86_64